.env by default, so the app in the container can’t read them.--cap-drop=ALL, --no-new-privileges, optional --read-only FS, and tmpfs for scratch.--network none if the app is offline‑capable.coolpkg==1.2.3) to reduce supply‑chain surprises.
.env exposure by default.--cap-drop=ALL, --no-new-privileges, optional --read-only filesystem.tmpfs scratch space (/tmp, /var/tmp) prevents writes to the image layer.--network none after building a Dockerfile image if your app is offline‑capable.--memory, --cpus, --pids-limit) to reduce blast radius.